OpenObserve: Self-Hosted Logs, Metrics and Traces - 夜莺博客

OpenObserve: Self-Hosted Logs, Metrics and Traces

Observability stacks tend to grow sideways: one system for logs, another for metrics, a third for traces, and an object store bill that scales faster than the traffic it describes. OpenObserve takes the opposite approach — a single Rust binary that ingests all three signal types and stores them in compressed columnar files, which makes a one-node deployment viable on a small VPS and keeps query costs predictable. This guide covers installation, the ingest paths you will actually use, and the operational settings that prevent a log flood from filling the disk.

What You Get in One Process

  • Ingest: logs via HTTP/OTLP/Fluent Bit/Vector/syslog, metrics via Prometheus remote_write and OTLP, traces via OTLP or Jaeger format, plus RUM events.
  • Query: SQL for logs and traces, PromQL for metrics — no proprietary query language.
  • Storage: Parquet with Zstd compression, locally or on any S3-compatible backend (MinIO, R2, B2).
  • Alerts and dashboards: built-in panels with time pickers, variables, and alert destinations including Slack, Teams, PagerDuty, webhook and email.

The resource profile is the headline: a single node idles in tens of megabytes of RAM, so it can share a 1 GB VPS with the applications it monitors. Multi-million-lines-per-day workloads want 2–4 GB and a proper disk budget instead.

Installation

Binary (quickest)

curl -L https://openobserve.ai/downloads/openobserve-latest-linux-amd64.tgz | tar xz
chmod +x openobserve
ZO_ROOT_USER_EMAIL="root@example.com" ZO_ROOT_USER_PASSWORD='Complexpass#123' ./openobserve
# UI on http://localhost:5080 — root credentials are required on first start only

Container (recommended for production)

docker run -d --name openobserve   -p 5080:5080   -e ZO_ROOT_USER_EMAIL=root@example.com   -e ZO_ROOT_USER_PASSWORD='Complexpass#123'   -e ZO_DATA_DIR=/data   -v openobserve_data:/data   public.ecr.aws/zinclabs/openobserve:latest

Put it behind TLS immediately if it is reachable from anywhere but localhost: the ingest endpoint authenticates with basic credentials and, without TLS, those credentials travel in clear text.

Sending Data In

Application logs over HTTP

curl -u root@example.com:'Complexpass#123'   -H "Content-Type: application/json"   http://localhost:5080/api/default/default/_json   -d '[{"level":"info","message":"deploy complete","service":"api","env":"prod"}]'
# -> {"code":200,"status":"ok","records":1}

The URL pattern is /api/<org>/<stream>/_json. Use a separate stream per application or per environment — retention, schemas and dashboards are all per-stream, and mixing production and staging logs in one stream makes both harder to manage.

Container logs with Fluent Bit

docker run -d --name fluent-bit   -v /var/lib/docker/containers:/var/lib/docker/containers:ro   fluent/fluent-bit:latest   /fluent-bit/bin/fluent-bit     -i tail -p path=/var/lib/docker/containers/*/*.log -p parser=docker     -o http -p host=YOUR_HOST -p port=5080        -p uri=/api/default/docker/_json -p format=json        -p http_user=root@example.com -p http_passwd='Complexpass#123'

Metrics with Prometheus remote_write

# prometheus.yml
remote_write:
  - url: http://YOUR_HOST:5080/api/default/prometheus/api/v1/write
    basic_auth:
      username: root@example.com
      password: "Complexpass#123"

Keeping the local Prometheus with 2–7 days of retention plus OpenObserve as the long-term store is a good hybrid: you keep fast local queries and stop paying for a giant local TSDB.

Network device logs over syslog

Point routers and switches at OpenObserve's syslog receiver, or run a small rsyslog relay that forwards to the HTTP endpoint — see our rsyslog central server guide for the relay pattern.

Retention, Storage and Cost

# Environment variables worth setting deliberately
ZO_LOG_RETENTION_DAYS=30          # or per-stream retention in the UI
ZO_COMPACT_DATA_RETENTION_DAYS=365
ZO_DATA_DIR=/data
ZO_S3_BUCKET=my-observability
ZO_S3_SERVER=https://s3.example.com
ZO_S3_ACCESS_KEY=... 
ZO_S3_SECRET_KEY=...

Two habits keep the bill predictable. First, set per-stream retention instead of one global value: application debug logs rarely justify 90 days, while firewall and AAA logs often do. Second, size the compaction window and disk with headroom — ingest bursts land as small files and compaction is what turns them into cheap long-term storage.

Operational Checklist

  1. Root password changed from the first-start value; TLS in front of port 5080.
  2. One stream per application/environment, with retention set per stream.
  3. Object storage configured before the local disk fills, not after.
  4. At least one alert wired to a destination a human actually reads.
  5. A weekly check that ingest volume matches expectation — unexplained growth is usually a debug flag left on.

Related reading: Grafana Loki and Promtail pipeline, VictoriaMetrics single-node vs cluster and Vector log pipelines.

原文链接:https://openobserve.ai/docs/getting-started